AWS Systems Manager (SSM) is a legitimate remote-administration channel, and it is one of the cleanest ways to run code on EC2 from the API alone. Any instance running the SSM agent with a role that allows it is reachable: no SSH key, no open port, no touching the metadata service. Command execution lands as root or SYSTEM, which then yields the instance role and on-host secrets.
What folds in here#
- Run command:
ssm:SendCommandto execute commands on one or many managed instances. - Session Manager:
ssm:StartSessionto open an interactive shell.
Finding managed instances#
aws ssm describe-instance-information --query 'InstanceInformationList[].InstanceId'